Protect dnat SSH from brute force

Hi all,

I wanted to ask if it is possible to protect from ssh brute force a dnated server published using mikrotik. I found a lot of articles for blacklisting ssh when the destination is the router it self but I did not find any for published servers.

Regards,
Ognyan